Description
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
Remediation
References
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-8005)
PHP Use After Free Vulnerability (CVE-2019-13224)
WordPress Plugin Essential Blocks Pro Multiple PHP Object Injection Vulnerabilities (1.1.0)
Drupal Core 6.x Multiple Vulnerabilities (6.0 - 6.5)
WordPress Plugin WP Statistics Multiple Unspecified Vulnerabilities (9.6.5)